← Vulnerability feed

Vulnerability record · CVE-2016-9589 · published 12 March 2018

CVE-2016-9589: Redhat jboss wildfly application server uncontrolled resource consumption vulnerability

Redhat · Jboss Wildfly Application Server

Undertow in Red Hat wildfly before version 11.0.0.Beta1 is vulnerable to a resource exhaustion resulting in a denial of service. Undertow keeps a cache of seen HTTP headers in persistent connections. It was found that this cache can easily exploited to fill memory with garbage, up to "max-headers" (default 200) * "max-header-size" (default 1MB) per active TCP connection.

7.5 CVSS 3.0 High EPSS 3.0% · top 13.3% CWE-400 · Uncontrolled resource consumption
7.5CVSS 3.0 base score, v2 5.0
3.0%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
26References
17 Jun 2026Last modified by NVD

Description

Undertow in Red Hat wildfly before version 11.0.0.Beta1 is vulnerable to a resource exhaustion resulting in a denial of service. Undertow keeps a cache of seen HTTP headers in persistent connections. It was found that this cache can easily exploited to fill memory with garbage, up to "max-headers" (default 200) * "max-header-size" (default 1MB) per active TCP connection.

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
http://rhn.redhat.com/errata/RHSA-2017-0830.html Vendor Advisory
http://rhn.redhat.com/errata/RHSA-2017-0831.html Vendor Advisory
http://rhn.redhat.com/errata/RHSA-2017-0832.html Vendor Advisory
http://rhn.redhat.com/errata/RHSA-2017-0834.html Vendor Advisory
http://rhn.redhat.com/errata/RHSA-2017-0876.html Vendor Advisory
http://www.securityfocus.com/bid/97060 Third Party AdvisoryVDB Entry
https://access.redhat.com/errata/RHSA-2017:0872 Vendor Advisory
https://access.redhat.com/errata/RHSA-2017:0873 Vendor Advisory
https://access.redhat.com/errata/RHSA-2017:3454 Vendor Advisory
https://access.redhat.com/errata/RHSA-2017:3455 Vendor Advisory
https://access.redhat.com/errata/RHSA-2017:3456 Vendor Advisory
https://access.redhat.com/errata/RHSA-2017:3458 Vendor Advisory
https://bugzilla.redhat.com/show_bug.cgi?id=1404782 Issue Tracking
http://rhn.redhat.com/errata/RHSA-2017-0830.html Vendor Advisory
http://rhn.redhat.com/errata/RHSA-2017-0831.html Vendor Advisory
http://rhn.redhat.com/errata/RHSA-2017-0832.html Vendor Advisory
http://rhn.redhat.com/errata/RHSA-2017-0834.html Vendor Advisory
http://rhn.redhat.com/errata/RHSA-2017-0876.html Vendor Advisory
http://www.securityfocus.com/bid/97060 Third Party AdvisoryVDB Entry
https://access.redhat.com/errata/RHSA-2017:0872 Vendor Advisory
https://access.redhat.com/errata/RHSA-2017:0873 Vendor Advisory
https://access.redhat.com/errata/RHSA-2017:3454 Vendor Advisory
https://access.redhat.com/errata/RHSA-2017:3455 Vendor Advisory
https://access.redhat.com/errata/RHSA-2017:3456 Vendor Advisory
https://access.redhat.com/errata/RHSA-2017:3458 Vendor Advisory
https://bugzilla.redhat.com/show_bug.cgi?id=1404782 Issue Tracking

Track CVE-2016-9589 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

7.5CVE-2015-3198Redhat jboss wildfly application server information exposure vulnerabilityThe Undertow module of WildFly 9.x before 9.0.0.CR2 and 10.x before 10.0.0.Alpha1 allows remote attackers to obtain the source code of a JSP page via…EPSS 1.8%7.5CVE-2016-0793Redhat jboss wildfly application server information exposure vulnerabilityIncomplete blacklist vulnerability in the servlet filter restriction mechanism in WildFly (formerly JBoss Application Server) before 10.0.0.Final on …EPSS 16%6.8CVE-2015-5188Redhat jboss enterprise application platform cross-site request forgery vulnerabilityCross-site request forgery (CSRF) vulnerability in the Web Console (web-console) in Red Hat Enterprise Application Platform before 6.4.4 and WildFly …EPSS 1.1%6.1CVE-2016-4993Redhat jboss enterprise application platform vulnerabilityCRLF injection vulnerability in the Undertow web server in WildFly 10.0.0, as used in Red Hat JBoss Enterprise Application Platform (EAP) 7.x before …EPSS 2.6%5.5CVE-2018-1047Redhat jboss wildfly application server improper input validation vulnerabilityA flaw was found in Wildfly 9.x. A path traversal vulnerability through the org.wildfly.extension.undertow.deployment.ServletResourceManager.getResou…EPSS 0.51%5.0CVE-2015-5220Redhat jboss enterprise application platform memory buffer overflow vulnerabilityThe Web Console in Red Hat Enterprise Application Platform (EAP) before 6.4.4 and WildFly (formerly JBoss Application Server) allows remote attackers…EPSS 3.0%4.3CVE-2015-5178Redhat jboss wildfly application server vulnerabilityThe Management Console in Red Hat Enterprise Application Platform before 6.4.4 and WildFly (formerly JBoss Application Server) does not send an X-Fra…EPSS 1.7%1.9CVE-2014-0018Redhat jboss enterprise application platform permissions and access controls vulnerabilityRed Hat JBoss Enterprise Application Platform (JBEAP) 6.2.0 and JBoss WildFly Application Server, when run under a security manager, do not properly …EPSS 0.35%

Source: NIST National Vulnerability Database (record CVE-2016-9589), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.